Privacy Policy
Our Commitment to Your Privacy
Hackable Pty Ltd (“we”, “our”, “us”) is a cybersecurity and penetration testing services provider.
We understand that our work often involves access to sensitive systems and information. Protecting your data is not just a legal requirement—it’s a core part of our responsibility as a security provider.
We handle personal information in accordance with the Privacy Act 1988 (Cth).
What We Collect (and Why)
We only collect information that is reasonably necessary to run our business and provide our services.
​
This includes:
-
Name, email address, and phone number
-
Company details and role
-
Information submitted via our quoting tool or contact forms
-
Records of communications with us
We collect personal information:
-
Directly from you (e.g. forms, emails, calls)
-
Through our website and quoting platform
-
During the delivery of our services
-
From third parties or public sources where appropriate
​
In the course of providing penetration testing services, we may also access:
-
Systems, applications, and networks
-
IP addresses, domains, and configurations
-
Security logs and technical data
We only access this information where authorised and within the agreed scope of our engagement.
​
We collect information to:
-
Provide quotes and respond to enquiries
-
Deliver penetration testing and cybersecurity services
-
Identify and report security vulnerabilities
-
Communicate with you during an engagement
-
Improve our services and platform
Where possible, we will explain why we are collecting information and how it will be used.
Information We May Access During Testing
As part of delivering penetration testing services, we may access:
-
Systems, applications, and networks
-
IP addresses, domains, and configurations
-
Security logs and technical data
We only access this information where authorised by you and strictly within the agreed scope of testing.
Sensitive Information
We do not intentionally collect sensitive personal information. If such information is encountered during testing, it will only be handled:
-
For the purpose of delivering the service
-
With appropriate care and confidentiality
-
In accordance with applicable laws
Disclosure of Personal Information
We may disclose personal information to:
-
Our employees and authorised contractors
-
Service providers who support our operations (e.g. hosting, infrastructure)
-
Professional advisers (legal, accounting, insurance)
-
Government or regulatory bodies where required by law
We take reasonable steps to ensure that third parties protect your information.
Data Security & Retention
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. While we take security seriously, no system is completely secure.
These steps include:
-
Access controls and least-privilege access
-
Secure storage of data and testing artefacts
-
Encryption where appropriate
-
Internal processes governing handling of sensitive information
​
We retain personal information only for as long as necessary to fulfill our services. When information is no longer required, we take reasonable steps to securely delete or de-identify it.
Security testing data (including logs, findings, and artefacts) is:
-
Deleted or anonymised as soon as reasonably practicable after reporting, unless otherwise agreed
-
Retained longer only where required for legal, contractual, or evidentiary purposes
​
Access and Corretions
You may request access to the personal information we hold about you and request correction if it is inaccurate, out of date, or incomplete. We will respond to such requests within a reasonable timeframe.
​
​
For any privacy-related enquiries or requests, please contact: info@hackable.com.au
​
​
We may update this Privacy Policy from time to time. The latest version will always be available on our website.